萬盛學電腦網

 萬盛學電腦網 >> 網絡編程 >> asp編程 >> asp 刪除數據庫記錄

asp 刪除數據庫記錄

asp教程 刪除數據庫教程記錄其實在asp中是很非常容易做的事情了,只要連接數據庫了,再利用sql delete函數來刪除就ok了,下面來看看實例吧。

id = saferequest("id")
sql="delete from table1 where whereid>"&id&""
rs.open sql,conn,1,3
response.write "<script>alert('刪除成功');location.href='del.asp';</script>"
set rs=nothing
set conn=nothing

這是過濾非法字符函數

function saferequest(paraname)
dim paravalue
paravalue=request(paraname)
if isnumeric(paravalue) = true then
saferequest=paravalue
exit function
elseif instr(lcase(paravalue),"select ") > 0 or instr(lcase(paravalue),"insert ") > 0 or instr(lcase(paravalue),"delete from") > 0 or instr(lcase(paravalue),"count(") > 0 or instr(lcase(paravalue),"drop table") > 0 or instr(lcase(paravalue),"update ") > 0 or instr(lcase(paravalue),"truncate ") > 0 or instr(lcase(paravalue),"asc(") > 0 or instr(lcase(paravalue),"mid(") > 0 or instr(lcase(paravalue),"char(") > 0 or instr(lcase(paravalue),"xp_cmdshell") > 0 or instr(lcase(paravalue),"exec master") > 0 or instr(lcase(paravalue),"net localgroup administrators") > 0 or instr(lcase(paravalue)," and ") > 0 or instr(lcase(paravalue),"net user") > 0 or instr(lcase(paravalue)," or ") > 0 or instr(lcase(paravalue),"""")>0 or instr(lcase(paravalue),"'")>0 then
response.write "請不要在函數中加入非法字符!"
response.end
else
saferequest=paravalue
end if
end function

copyright © 萬盛學電腦網 all rights reserved